Security Awareness & Training
- All employees participate in an ongoing security awareness program, including short-form monthly training and quarterly instructor-led sessions, supplemented by a dedicated new-hire onboarding track.
- Training content is risk-aligned, with targeted material for higher-risk audiences such as executives and finance.
- Recurring phishing simulations are conducted, with engagement reinforced by linking simulation performance to performance incentives.
Framework Alignment: NIST CSF PR.AT; CIS Control 14; GDPR Art. 32, 39; ISO 27001:2022 A.6.3